# Elastic prebuilt rules error

**URL:** <https://discuss.elastic.co/t/elastic-prebuilt-rules-error/334086>\
**Category:** Elastic Security\
**Created:** [May 23, 2023, 7:26am UTC](https://discuss.elastic.co/t/elastic-prebuilt-rules-error/334086 "2023-05-23T07:26:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hasan.idriss](https://avatars.discourse-cdn.com/v4/letter/h/e79b87/32.png) [@hasan.idriss](https://discuss.elastic.co/u/hasan.idriss)\
**Post date:** [May 23, 2023, 7:26am UTC](https://discuss.elastic.co/t/elastic-prebuilt-rules-error/334086/1 "2023-05-23T07:26:37Z")

</div>

hi guys am facing an issue with all prebuilt rules in Elasticsearch, when I enable the rules it runs with the following error

```auto
An error occurred during rule execution: message: "verification_exception

Root causes:

verification_exception: Found 4 problems

line 2:4: Unknown column [event.category], did you mean any of [event.action, event.code, event.created, event.outcome, event.code.keyword, event.action.keyword, event.kind.keyword]?

line 3:5: Unknown column [winlog.logon.type], did you mean any of [winlog.user.type, winlog.event_id, winlog.opcode, winlog.user.name, winlog.activity_id, winlog.event_data.Type]?

line 4:5: Unknown column [source.ip]

line 4:79: Unknown column [user.name], did you mean any of [agent.name, winlog.user.name, host.name, host.os.name]?"

```

this error is on the rule with name "Privileged Account Brute Force"  
I am using the winlogbeat  
but it seems that the issue on all rules since the fields mapping differs between the rules and the winlogbeat index

the rule EQL syntax is

```auto
sequence by winlog.computer_name, source.ip with maxspan=10s
  [authentication where host.os.type == "windows" and event.action == "logon-failed" and
    winlog.logon.type : "Network" and
    source.ip != null and source.ip != "127.0.0.1" and source.ip != "::1" and user.name : "*admin*" and

    /* noisy failure status codes often associated to authentication misconfiguration */
    not winlog.event_data.Status : ("0xC000015B", "0XC000005E", "0XC0000133", "0XC0000192")] with runs=5

```

---

<div class="post-metadata">

**Author:** ![sholzhauer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sholzhauer/32/110282_2.png) [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Post date:** [June 19, 2023, 1:03pm UTC](https://discuss.elastic.co/t/elastic-prebuilt-rules-error/334086/2 "2023-06-19T13:03:48Z")

</div>

Hi @hasan.idriss,

Most of the times I have come across this it is due to a mapping issue.  
The detection rules (security application in general) needs the correct ECS mappings,  
when you look at stack management --\> dataviews --\> winlogbeat-\*  
are there any mapping conflicts? You can find them with the type dropdown and selecting `conflict`.

After this, continue checking the index mappings on the different data views and indices.

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [June 19, 2023, 6:56pm UTC](https://discuss.elastic.co/t/elastic-prebuilt-rules-error/334086/3 "2023-06-19T18:56:32Z")

</div>

My rule is active and functional, however, I use the Elastic Agent with the System and Windows integrations. What might be happening is that this rule needs some fields mapped to the Elastic Agent integrations. I ran into a similar problem on a detection rule that needed packetbeat.

 ![print_elastic_discusse](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a71fbefc819a7d1bab27f7acaeeafe8a2cbeecc8.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2023, 6:57pm UTC](https://discuss.elastic.co/t/elastic-prebuilt-rules-error/334086/4 "2023-07-17T18:57:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
